Product
unix4lyfe darkhttpd
3 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-23771
CVE-2024-23770
CVE-2020-25691
< 1.15
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attacker
<= 1.15
darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.
<= 1.13-1
A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with